TL;DR The Apache Tomcat team fixed 11 vulnerabilities on August 25, 2026. The batch includes three Important...
Authentication Bypass
TL;DR CISA disclosed 11 Ebyte NE2-D11 vulnerabilities on August 25, 2026. Four carry a critical 9.8 CVSS...
TL;DR CERT/CC disclosed five RDK-B WebUI vulnerabilities on August 19, 2026. The worst flaw lets a remote,...
CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
CVE-2026-20315 & CVE-2026-20317: Cisco Secure Workload Auth Bypass, Privilege Escalation Hit CVSS 10
TL;DR Cisco released hardening updates for Secure Workload on August 19, 2026. The Cisco Secure Workload authentication...
TL;DR Citrix patched a critical NetScaler authentication bypass tracked as CVE-2026-19490. It scores 9.3 on CVSS v4....
IBM patched 18 flaws in Db2 Mirror for i this week. The worst bug lets a remote...
TL;DR: A critical User Profile Builder vulnerability, carrying a maximum CVSS score of 9.8 and tracked as...
TL;DR TP-Link disclosed five vulnerabilities across its ISP-managed networking gear. The flaws hit mesh systems, routers, PON...
TL;DR HPE Aruba Networking patched two critical flaws in its SD-WAN EdgeConnect Orchestrator. Both carry a CVSS...
TL;DR Two critical Puwell IP Camera vulnerabilities now have public details and proof-of-concept exploit code. Both score...
TL;DR Rapid7 has published a technical analysis and a working proof-of-concept for CVE-2026-55040. The flaw is a...
TL;DR Progress released an August 2026 bulletin for MarkLogic Server. It fixes ten MarkLogic Server vulnerabilities, several...
TL;DR A high-severity authentication bypass affects the Neo4j GraphQL Library before versions 7.5.6 and 5.12.14. Tracked as...
TL;DR WSO2 disclosed four critical vulnerabilities across its API and identity products. Several are WSO2 account takeover...
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete...
TL;DR: Check Point patched a Check Point authentication bypass affecting its Security Management and Multi-Domain Security Management...
TL;DR CERT/CC disclosed an Arris BGW210-700 vulnerability tracked as CVE-2026-16771. The authentication bypass affects firmware 2.7.7 and...
TL;DR SolarWinds has patched a critical authentication bypass in SolarWinds Web Help Desk. Tracked as CVE-2026-28323, the...
TL;DR A critical OpenRemote vulnerability, CVE-2026-66013, carries a CVSS score of 9.3. It lets an unauthenticated attacker...
TL;DR Attackers are exploiting a SmartConsole authentication bypass in Check Point management servers. The flaw, CVE-2026-16232, lets...
A critical Konnectivity vulnerability lets a remote attacker slip into a cluster without any credentials. Tracked as...
TL;DR CISA published advisory ICSA-26-202-01 on July 21, 2026. It covers a critical Tycon authentication bypass in...